TL;DR: Zero Trust programmes often stall after MFA and admin hardening because only 16% of organisations cover most of their systems, users and infrastructure, according to JumpCloud citing Gartner; a phased rollout moves teams from foundational controls to contextual access and then to automation and scale. Zero Trust only scales when it is treated as an operating model, not a one-time project.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “Why Zero Trust Needs to Be Rolled Out in Phases”.
By the numbers:
- Only 16% of organisations have Zero Trust protections covering most of their systems, users and infrastructure.
- According to Gartner, 16% of organisations have Zero Trust protections covering most of their systems, users and infrastructure.
Key questions
Q: What should teams do first when zero trust is still only partially deployed?
A: Start with the controls that remove the most obvious exposure: MFA, least privilege, shared credential protection and removal of default admin accounts.
Q: Why do zero trust programmes often stall after MFA and admin hardening?
A: They stall because early wins are easier than extending policy across legacy systems, disconnected tools and unmanaged devices.
Q: What are the signs that a zero trust rollout is failing in practice?
A: Common warning signs include overlapping tools that do not integrate well, inconsistent policy enforcement across environments, weak visibility into asset and transaction flows, and users bypassing controls because processes are too cumbersome.
Practitioner guidance
- Sequence Zero Trust by control maturity Start with MFA, least privilege, shared credential protection, default admin removal and protocol cleanup before expanding to contextual access and automation.
- Expand conditional access using trusted signals Use device health, location and behavioural context to make access decisions more specific, and govern unmanaged devices before extending coverage further.
- Automate identity lifecycle operations Connect provisioning, deprovisioning, logging and policy review so Zero Trust does not depend on manual follow-up as the environment grows.
Bottom line: The article argues that Zero Trust fails to scale when organisations stop at MFA and admin hardening instead of sequencing broader access controls.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Phased rollout is the only practical way to turn Zero Trust into an operating model. The article is right to reject the idea that Zero Trust can be deployed as a single project milestone. Access control maturity has to move from foundational authentication to contextual policy and then to automated operations, or it stalls at the first layer of defence. For practitioners, the important shift is to manage Zero Trust as a governed progression, not a destination.
A few things that frame the scale:
- 90% of IT leaders say properly managing NHIs is essential for a successful zero-trust implementation, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: How should IAM teams decide when to extend zero trust to more systems?
A: Extend coverage when foundational controls are stable, access decisions can use reliable context, and lifecycle operations are automated enough to sustain change. If the organisation still depends on manual provisioning or inconsistent logging, widening scope will increase complexity faster than it reduces risk.
👉 Read our full editorial: Phased zero trust rollout is the key to scaling access control